NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1052 most downloaded on npm
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It runs as JavaScript and works in all modern browsers, as well as in Node.js (via jsdom). DOMPurify is written by security people who have vast background in web a
Last release 11 days ago
23 Sep 2026
Release timing varies
gaps range from 2 weeks to 3 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
4 versions withdrawn
withdrawn after publishing
12 years old
153 releases · first in 2014
Fixed a problem with IN_PLACE node removal when working with hooks, thanks @manus-pi
IN_PLACE node removal when working with hooks, thanks @manus-piIN_PLACE sanitization and raw-text roots, thanks @h-t-mrollup to rolldown because performance, thanks @ssi02014Added better clobbering hardening when XML content is involved, thanks @gnyselcuk
One column per quarter.
Fixed an issue with possible bypasses when risky tags are allow-listed, thanks @alirezarouhbakhsh
pointer-events and vector-effect presentation attributes to the allow-list, thanks @JaybhadeFixed an issue with hook removal during IN_PLACE sanitization, thanks @koyokr
IN_PLACE sanitization, thanks @koyokrownerDocument during IN_PLACE, thanks @AkshayJainGFixed an issue where a hook would not get called for custom elements, thanks @Rikuxx0
Bumped vulnerable development dependencies to arrive at plain 0 with npm audit
setConfig, thanks @trace37labsnpm auditosv-scanner suppression list as no vulnerable dependencies are left for nowRefactored codebase for clarity: extracted the public type declarations into types.ts
types.tsSAFE_FOR_TEMPLATES scrubbing into single shared pathtextContent before innerHTMLnpm run bench) with a --compare modedemos/ folder so every demo runs again, and added a SVG-via-<img> demotest:happydom scripts in the READMEFurther improved the handling of Trusted Types config options, thanks @offset
IN_PLACE sanitization, thanks @mozfreddybIN_PLACE and Trusted Types related usageCleaned up the repository root, renamed some and removed unneeded files
Hardened the handling of Shadow Roots when using IN_PLACE, thanks @GameZoneHacker
IN_PLACE, thanks @GameZoneHackerFixed several issues with DOM Clobbering in IN_PLACE mode, thanks @offset & @Bankde
IN_PLACE mode, thanks @offset & @BankdeIN_PLACE and Shadow DOM sanitization, thanks @offset & @BankdeIN_PLACE and general DOM Clobbering attacksNote that this is a security release for an issue introduced in 3.4.4 and should be upgraded to immediately.
selectedcontent added in 3.4.4, thanks @KabirAcharyaNote that this is a security release for an issue introduced in 3.4.4 and should be upgraded to immediately.
🚨 This release had been flagged as deprecated, please use DOMPurify 3.4.5 instead 🚨
selectedcontent element to default allow-list, thanks @lukewarlowcommand and commandfor attributes to default allowed-list, thanks @lukewarlowIN_PLACE operations, thanks @DEMON1A🚨 This release had been flagged as deprecated, please use DOMPurify 3.4.5 instead 🚨
Fixed an issue with handling of nested Shadow DOM trees, thanks @fishjojo1
Fixed an issue with URI validation on attributes allowed via ADD_ATTR callback, thanks @nelstrom
ADD_ATTR callback, thanks @nelstromFixed an issue with on-handler stripping for HTML-spec-reserved custom element names (font-face, color-profile, missing-glyph, font-face-src, font-fac
font-face, color-profile, missing-glyph, font-face-src, font-face-uri, font-face-format, font-face-name) under permissive CUSTOM_ELEMENT_HANDLINGannotation-xml check that allowed mixed-case variants to bypass the basic-custom-element exclusion in XHTML modeSANITIZE_NAMED_PROPS repeatedly prefixing already-prefixed id and name values on subsequent sanitizationIN_PLACE root-node check to explicitly guard against non-string nodeName (DOM-clobbering robustness)slot entry from the default HTML attribute allow-listSANITIZE_NAMED_PROPS, and a negative-control assertion ensuring the invariants actually fireSAFE_FOR_TEMPLATES greedy scrub, hook-added attribute handling)3.x and 2.x maintenance branchesFixed a problem with FORBID_TAGS not winning over ADD_TAGS, thanks @kodareef5
Most relevant changes:
FORBID_TAGS not winning over ADD_TAGS, thanks @kodareef5ADD_ATTR/ADD_TAGS function leaking into subsequent array-based calls, thanks @1Jesper1SAFE_FOR_TEMPLATES scrub in RETURN_DOM path, thanks @bencalifCUSTOM_ELEMENT_HANDLING, thanks @trace37labsADD_TAGS function form bypassing FORBID_TAGS, thanks @eddieranADD_ATTR predicates skipping URI validation, thanks @christos-ethUSE_PROFILES prototype pollution, thanks @christos-ethPublished Advisories are here: https://github.com/cure53/DOMPurify/security/advisories?state=published
Fixed an engine requirement for Node 20 which caused hiccups, thanks @Rotzbua
Fixed a possible bypass caused by jsdom's faulty raw-text tag parsing, thanks multiple reporters
_isValidAttribute, thanks @christos-ethUpdated ADD_FORBID_CONTENTS setting to extend default list, thanks @MariusRumpf
ADD_FORBID_CONTENTS setting to extend default list, thanks @MariusRumpfAdded the SVG mask-type attribute to default allow-list, thanks @prasadrajandran
mask-type attribute to default allow-list, thanks @prasadrajandranADD_ATTR and ADD_TAGS to accept functions, thanks @nelstromslot element being in both SVG and HTML allow-list, thanks @Wim-ValgaerenAdded new attributes and elements to default allow-list, thanks @elrion018
tagName parameter to custom element attributeNameCheck, thanks @nelstromhref attributes, thanks @llamakkoRemoved the script that caused the fake entry CVE-2025-48050
matrix: as an allowed URI scheme, thanks @kleinesfilmroellchenAdded a check to the mXSS detection regex to be more strict, thanks @masatokinugawa
ALLOWED_URI_REGEXP using the 'g' flag, thanks @hhk-pngFixed a conditional and config dependent mXSS-style bypass reported by @nsysean
Fixed two conditional sanitizer bypasses discovered by @parrot409 and @Slonser
Fixed a possible bypass in case a rather specific config for custom elements is set, thanks @yaniv-git
Fixed several minor issues with the type definitions, thanks @reduckted @ghiscoding @asamuzaK @MiniDigger
Added type declarations, thanks @reduckted , @philmayfield, @aloisklink, @ssi02014 and others
Fixed an issue with comment detection and possible bypasses with specific config settings, thanks @masatokinugawa
foreignObject element from the list of HTML entry-points, thanks @masatokinugawaFixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks @kevin-mizu
Fixed a minor issue with the dist paths in bower.js, thanks @HakumenNC
bower.js, thanks @HakumenNCFixed an issue with the recently implemented isNaN checks, thanks @tulach
isNaN checks, thanks @tulachFixed several mXSS variations found by and thanks to @kevin-mizu & @Ry0taK
nodeType property, thanks @ssi02014Addressed and fixed a mXSS variation found by @kevin-mizu
Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
Added new setting SAFE_FOR_XML to enable better control over comment scrubbing
SAFE_FOR_XML to enable better control over comment scrubbingFixed another conditional bypass caused by Processing Instructions, thanks @Ry0taK
Fixed two possible bypasses when sanitizing an XML document and later using it in HTML, thanks @Slonser
Fixed a problem with proper detection of Custom Elements, thanks @kevin-mizu
hasOwnProperty logic, thanks @ssi02014console.warn making HappyDom happier, thanks @HugoPoiFixed errors caused by conditional exports, thanks @ssi02014
Added better protection against CSPP attacks, thanks @kevin-mizu
Refactored the core code-base and several utilities, thanks @ssi02014
Fixed a licensing issue spotted and reported by @george-thomas-hill
Fixed a bypass in jsdom 22 in case the noframes element is permitted, thanks @leeN
shadowrootmod which should be shadowrootmode, thanks @masatokinugawaAdded new TRUSTED_TYPES_POLICY configuration option, thanks @dejang
TRUSTED_TYPES_POLICY configuration option, thanks @dejangfeDropShadow to the SVG filter allow-list, thanks @SelfMadeSystemFixed an issue with ALLOWED_URI_REGEXP not being reset, thanks @mukilane
ALLOWED_URI_REGEXP not being reset, thanks @mukilanemprescripts tag to allowed MathML elements, thanks @duyhai94Fixed a problem with improper reset of custom HTML options, thanks @ammaraskar
Removed all code that is for MSIE-only
ALLOW_SELF_CLOSE_IN_ATTR flag, thanks @edg2s @AndreVirtimoshadowrootmode, thanks @mfreed7NOTE Please use the 2.4.4 release if you still need MSIE support, 3.0.0 comes without the MSIE overhead
Fixed a possible bypass caused by jsdom's faulty raw-text tag parsing
Fixed two conditional sanitizer bypasses discovered by @parrot409 and @Slonser
Fixed an issue with comment detection and possible bypasses with specific config settings, thanks @masatokinugawa
foreignObject element from the list of HTML entry-points, thanks @masatokinugawaFixed an issue with the execution logic of attribute hooks to prevent bypasses, thanks @kevin-mizu
Fixed a minor issue with the dist paths in bower.js, thanks @HakumenNC
bower.js, thanks @HakumenNCFixed a bug with latest isNaN checks affecting MSIE, thanks @tulach
isNaN checks affecting MSIE, thanks @tulachFixed several mXSS variations found by and thanks to @kevin-mizu & @Ry0taK
Addressed and fixed a mXSS variation found by @kevin-mizu
Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
Note that this is a security release and should be upgraded to immediately. Please also note that further releases may follow as the underlying vulnerability is apparently new and further variations may be discovered.
Added new setting SAFE_FOR_XML to enable better control over comment scrubbing
SAFE_FOR_XML to enable better control over comment scrubbingFixed another conditional bypass caused by Processing Instructions, thanks @Ry0taK
Your coding agent can read these notes before it upgrades. Set up the MCP server →